Forum Discussion

xavmoss_167032's avatar
xavmoss_167032
Icon for Nimbostratus rankNimbostratus
Nov 04, 2015

Machine Certificate failed in some user.

I have problem with machine certificate check. In some user can identify certificate just fine but in some user have a problem . Log from F5 APM

Certificate is not found in this computer
session.check_machinecert.last.certificate_revoked  0
session.check_machinecert.last.certificate_verified 0
session.check_machinecert.last.error_message X509_verify_cert failed: error : 20 at depth 0, error message:unable to get local issuer certificate 
session.check_machinecert.last.result 0
session.check_machinecert.last.signature_verified 1
fallbackCert LoggingFailure
FailureInternalCheckFailure
FailureLogonDeny
Logon_Deny

But when debug using f5wininfo.exe, log from user is shown that f5 service found certificate Log from f5wininfo.exe

48,2015-11-04,8:32:41:118,,6284,6984,Store name:"MY", Store location:"CurrentUser", Subject match FQDN:"false", Allow elevation UI:"true", Serial number(HEX):"", Issuer:"", SubjectAltName:""
48,2015-11-04,8:32:41:118,,6284,6984,certInfo:STORE_NAME:MY&STORE_LOCATION:CurrentUser&ALLOW_ELEVATION:1&MATCH_FQDN:0&SN:&ISSUER:&SAN:&, RootCertInfo:IS_TRUSTED:0, Nonce: YXlIZ3dZcE1TV21lT0hPSkZYMm4=
48,2015-11-04,8:32:41:134,,6284,6984,found matched certificate
48,2015-11-04,8:32:41:134,,6284,6984,Total certs tested: 1
48,2015-11-04,8:32:41:134,,6284,6984,fqdn:
48,2015-11-04,8:32:41:321,,6284,6984,Signing message succeeded
48,2015-11-04,8:32:41:321,,6284,6984,The machine certificate has private key on this machine
48,2015-11-04,8:32:41:321,,6284,6984,GetPrivateKey succeeded: found private key.
48,2015-11-04,8:32:41:368,,6284,6984,CUAgentHost::downloadNextAgent() - POST data

Can anyone help me with this problem?

2 Replies

  • How is your Trusted Certificate Authoritied (in SSL Profile-Certificate Authority) configured? Does it contains the full chain?
  • The logs can be a little misleading on the client. Do you have multiple machine certificates on the client? If so try to add a issuer string in the VPE config for the machine certificate.

     

    Seth